1. Data Controller
The data controller for your personal data is:
Mathis Higuinen
Square Charles Hercules de Keranflec'h 23
35000 Rennes, France
E-mail : [email protected]
2. Data Collected
We collect different categories of data depending on your use of Orizn:
Data provided by you
- Account information: first name, last name, email address, profile picture
- Traveler profile: nationality, interests, favorite destinations
- Published content: spots, photos, comments, travel stories
- Messages exchanged with other users
Automatically collected data
- Geolocation data (with your consent)
- Technical data: IP address, device type, operating system, browser
- Usage data: pages visited, features used, session duration
- Cookie and tracker identifiers
3. Use of Data
We use your data to:
- Provide and improve the Platform's Services
- Manage your account and personalize your experience
- Display nearby travelers on the map (with your consent)
- Connect you with other travelers
- Send you notifications related to your activity
- Ensure Platform security and combat fraud
- Analyze service usage for improvement (analytics)
- Send you marketing communications (with your consent)
- Comply with our legal obligations
4. Legal Basis (GDPR)
In accordance with Article 6 of the GDPR, the processing of your data is based on the following legal grounds:
Performance of a contract—Processing necessary for the provision of Services (account management, platform features).
Consent—Geolocation, marketing communications, analytics cookies. You may withdraw your consent at any time.
Legitimate interest—Service improvement, platform security, fraud prevention.
Legal obligation—Retention of certain data required by French legislation.
5. Retention Period
We retain your personal data as long as your account is active. Upon account deletion:
- Account data : deleted within 30 days
- Published content : anonymized or deleted within 30 days
- Billing data : retained for 10 years (legal obligation)
- Technical logs : retained for a maximum of 12 months
- Anonymized data : retained without limitation for statistical purposes
6. Subprocessors & Third Parties
We share your data only with trusted subprocessors, strictly for the operation of the Platform:
| Service | Usage | Location |
|---|---|---|
| Cloudflare | CDN, security, DNS | Global (EU included) |
| Hetzner | Server hosting | Germany (EU) |
| Stripe | Payments | EU / USA |
| PostHog | Product analytics | EU |
| Resend | Transactional emails | USA |
| Apple | Authentication (Sign in with Apple) | USA |
We never sell your personal data to third parties. We only share your data with the subprocessors listed above and, where applicable, with the competent authorities if required by law.
7. International Transfers
Some of our subprocessors are located outside the European Economic Area (EEA). In such cases, we ensure that appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- EU-US Data Privacy Framework (DPF) for certified providers
8. Your Rights
Under the GDPR, you have the following rights over your personal data:
Right of access—Obtain a copy of your personal data.
Right of rectification—Correct inaccurate or incomplete data.
Right to erasure—Request the deletion of your data.
Right to data portability—Receive your data in a structured, machine-readable format.
Right to object—Object to the processing of your data on legitimate grounds.
Right to restriction—Request the restriction of processing in certain cases.
Withdrawal of consent—Withdraw your consent at any time, without affecting the lawfulness of prior processing.
To exercise your rights, contact us at [email protected]. We will respond within 30 days.
You also have the right to file a complaint with the CNIL (French Data Protection Authority): www.cnil.fr
10. Minors
Orizn is not intended for children under 16 years of age. We do not knowingly collect personal data from minors under 16. If we learn that a minor under 16 has provided us with personal data, we will delete it as soon as possible.
11. Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, alteration, or disclosure:
- Encryption of data in transit (TLS/HTTPS)
- Encryption of data at rest
- Strict access control to systems
- Regular backups
- Security monitoring and alerts
12. Changes
We may update this Privacy Policy at any time. In the event of material changes, we will notify you by notification in the application or by email.
The date of the last update is indicated at the top of this page. We encourage you to review this page regularly.
13. Contact
For any questions regarding the protection of your personal data or to exercise your rights, contact us:
Square Charles Hercules de Keranflec'h 23, 35000 Rennes, France
E-mail : [email protected]